The Global Privacy Enforcement Network was established in 2010 on the recommendation of the Organisation for Economic Co-operation and Development (OECD). Ten years after the first survey on the use of websites and apps by children conducted in 2015, the 2025 investigation provides us with updated data based on a sample of 900 sites and the involvement of 27 data protection authorities from various countries.
Lights and shadows emerge from the information collected: on one hand, sensitivity is growing among authorities, professionals, institutions, and privacy protection associations regarding the need for control that starts from the production of sources and reaches verification of end-user habits. On the other hand, the monitoring highlighted negligence regarding how easily minors are asked (unless carefully prompted not to) to provide their personal data already upon entering social media platforms. Compared to 2015, there is an increase in these intrusions into children’s privacy, and it is a slow but exponential growth that must be stopped also because such information—once obtained—could be shared with third parties.
Media overexposure exists and is the most pernicious vulnerability of this web navigation: it suffices to remember that the most odious crime enabled by access to personal data and images is so-called ‘revenge porn,’ a growing and devastating phenomenon in terms of violations of protections that should be guaranteed. Barriers to the circulation of private information can be easily circumvented, which is a particular concern if inappropriate content or data processing and design features pose a high risk to children. In short, although control during platform use is possible, the highest security to avoid violating the ethical code and to ensure absolute protection of minor users’ data and their content could be achieved with more targeted protection at the source-setting level: this is an already raised issue and a requested measure because if the imprinting is fraudulent, any corrective or censorship attempts made afterwards prove elusive and ineffective.
The survey was conducted starting from the preparation of a grid of 5 indicators useful for data collection and classification: 1) age verification for site access, 2) collection of data concerning minor users, 3) detection of protection controls, 4) account deletion, 5) exercising the ability to limit risks of manipulation of inappropriate content.
The monitoring of the collected data allowed the following findings in order: 1) 72% of platform users bypassed age verification, including via self-declaration, 2) 59% of websites requested access with an email address, 46% with geolocation, and even 50% with full name accreditation, 3) 71% did not provide indications on protection controls targeted at children, 4) 36% did not allow easy deletion of access via account, 5) only 35% of platforms offered minors the possibility to ask parental permission to continue web navigation.
The reading of the data collected in the monitoring and the breadth of cross-border cooperation among privacy regulatory authorities in an increasingly globalized market (the network includes 80 member countries worldwide) allows for knowledge opportunities and the increasingly targeted preparation of measures to protect minors at the legislative and control levels.




